Skip to content
Benchmarks

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

1,440 test files. Secrets in formats the provider itself documents. Expected: hidden.

redact-secret0.1.0-beta.14
99%1,422 of 1,440 hidden
  • Hidden 1,422
  • Partly readable 2
  • Readable 16
flare-redact1.6.1
37%531 of 1,440 hidden
  • Hidden 531
  • Partly readable 23
  • Readable 886
Show the 891 files with different results

2 / 2

Safe text that must be left alone

167 test files. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%167 of 167 left alone
  • Left alone 167
  • Flagged 0
flare-redact1.6.1
96%161 of 167 left alone
  • Left alone 161
  • Flagged 6
Show the 6 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

468 test files whose provider family one of flare-redact’s rules targets. Secrets in formats the provider itself documents. Expected: hidden.

redact-secret0.1.0-beta.14
99%464 of 468 hidden
  • Hidden 464
  • Partly readable 0
  • Readable 4
flare-redact1.6.1
90%421 of 468 hidden
  • Hidden 421
  • Partly readable 18
  • Readable 29
Show the 43 files with different results

2 / 2

Safe text that must be left alone

65 test files whose provider family one of flare-redact’s rules targets. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%65 of 65 left alone
  • Left alone 65
  • Flagged 0
flare-redact1.6.1
94%61 of 65 left alone
  • Left alone 61
  • Flagged 4
Show the 4 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

548 test files. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.

redact-secret0.1.0-beta.14
98%539 of 548 hidden
  • Hidden 539
  • Partly readable 3
  • Readable 6
flare-redact1.6.1
34%188 of 548 hidden
  • Hidden 188
  • Partly readable 14
  • Readable 346
Show the 351 files with different results

2 / 2

Safe text that must be left alone

1,866 test files. Look-alikes and near misses of those formats. Expected: left alone.

redact-secret0.1.0-beta.14
99%1,852 of 1,866 left alone
  • Left alone 1,852
  • Flagged 14
flare-redact1.6.1
96%1,798 of 1,866 left alone
  • Left alone 1,798
  • Flagged 68
Show the 78 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

195 test files whose provider family one of flare-redact’s rules targets. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.

redact-secret0.1.0-beta.14
95%186 of 195 hidden
  • Hidden 186
  • Partly readable 3
  • Readable 6
flare-redact1.6.1
77%151 of 195 hidden
  • Hidden 151
  • Partly readable 5
  • Readable 39
Show the 35 files with different results

2 / 2

Safe text that must be left alone

555 test files whose provider family one of flare-redact’s rules targets. Look-alikes and near misses of those formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%555 of 555 left alone
  • Left alone 555
  • Flagged 0
flare-redact1.6.1
90%497 of 555 left alone
  • Left alone 497
  • Flagged 58
Show the 58 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

Hidden by default

Project policy is this project’s own masking rule. Other tools are not built to follow it, so a difference here reflects scope, not accuracy. Show anyway.

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

1,006 test files. Values this project’s own masking policy hides. Expected: hidden.

redact-secret0.1.0-beta.14
94%948 of 1,006 hidden
  • Hidden 948
  • Partly readable 2
  • Readable 56
flare-redact1.6.1
39%395 of 1,006 hidden
  • Hidden 395
  • Partly readable 13
  • Readable 598
Show the 553 files with different results

2 / 2

Safe text that must be left alone

1,880 test files. Text this project’s policy leaves alone. Expected: left alone.

redact-secret0.1.0-beta.14
99.5%1,871 of 1,880 left alone
  • Left alone 1,871
  • Flagged 9
flare-redact1.6.1
97%1,832 of 1,880 left alone
  • Left alone 1,832
  • Flagged 48
Show the 49 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

Hidden by default

Project policy is this project’s own masking rule. Other tools are not built to follow it, so a difference here reflects scope, not accuracy. Show anyway.

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Runtime library

flare-redact1.6.1

Built to redact secrets and personal data from text at runtime. Run secrets-only here: its personal-data and generic-assignment detectors are off.

Ran as: Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

365 test files whose provider family one of flare-redact’s rules targets. Values this project’s own masking policy hides. Expected: hidden.

redact-secret0.1.0-beta.14
95%345 of 365 hidden
  • Hidden 345
  • Partly readable 1
  • Readable 19
flare-redact1.6.1
86%315 of 365 hidden
  • Hidden 315
  • Partly readable 11
  • Readable 39
Show the 30 files with different results

2 / 2

Safe text that must be left alone

339 test files whose provider family one of flare-redact’s rules targets. Text this project’s policy leaves alone. Expected: left alone.

redact-secret0.1.0-beta.14
100%339 of 339 left alone
  • Left alone 339
  • Flagged 0
flare-redact1.6.1
92%311 of 339 left alone
  • Left alone 311
  • Flagged 28
Show the 28 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • flare-redact 1.6.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 1.6.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

1,440 test files. Secrets in formats the provider itself documents. Expected: hidden.

redact-secret0.1.0-beta.14
99%1,422 of 1,440 hidden
  • Hidden 1,422
  • Partly readable 2
  • Readable 16
gitleaks8.30.1
65%939 of 1,440 hidden
  • Hidden 939
  • Partly readable 18
  • Readable 483
Show the 487 files with different results

2 / 2

Safe text that must be left alone

167 test files. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%167 of 167 left alone
  • Left alone 167
  • Flagged 0
gitleaks8.30.1
94%157 of 167 left alone
  • Left alone 157
  • Flagged 10
Show the 10 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

635 test files whose provider family one of gitleaks’ rules targets. Secrets in formats the provider itself documents. Expected: hidden.

redact-secret0.1.0-beta.14
99%631 of 635 hidden
  • Hidden 631
  • Partly readable 0
  • Readable 4
gitleaks8.30.1
86%544 of 635 hidden
  • Hidden 544
  • Partly readable 18
  • Readable 73
Show the 89 files with different results

2 / 2

Safe text that must be left alone

56 test files whose provider family one of gitleaks’ rules targets. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%56 of 56 left alone
  • Left alone 56
  • Flagged 0
gitleaks8.30.1
91%51 of 56 left alone
  • Left alone 51
  • Flagged 5
Show the 5 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

548 test files. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.

redact-secret0.1.0-beta.14
98%539 of 548 hidden
  • Hidden 539
  • Partly readable 3
  • Readable 6
gitleaks8.30.1
70%382 of 548 hidden
  • Hidden 382
  • Partly readable 3
  • Readable 163
Show the 157 files with different results

2 / 2

Safe text that must be left alone

1,866 test files. Look-alikes and near misses of those formats. Expected: left alone.

redact-secret0.1.0-beta.14
99%1,852 of 1,866 left alone
  • Left alone 1,852
  • Flagged 14
gitleaks8.30.1
94%1,745 of 1,866 left alone
  • Left alone 1,745
  • Flagged 121
Show the 115 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

268 test files whose provider family one of gitleaks’ rules targets. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.

redact-secret0.1.0-beta.14
97%259 of 268 hidden
  • Hidden 259
  • Partly readable 3
  • Readable 6
gitleaks8.30.1
82%219 of 268 hidden
  • Hidden 219
  • Partly readable 3
  • Readable 46
Show the 40 files with different results

2 / 2

Safe text that must be left alone

825 test files whose provider family one of gitleaks’ rules targets. Look-alikes and near misses of those formats. Expected: left alone.

redact-secret0.1.0-beta.14
99%818 of 825 left alone
  • Left alone 818
  • Flagged 7
gitleaks8.30.1
90%743 of 825 left alone
  • Left alone 743
  • Flagged 82
Show the 75 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

Hidden by default

Project policy is this project’s own masking rule. Other tools are not built to follow it, so a difference here reflects scope, not accuracy. Show anyway.

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

1,006 test files. Values this project’s own masking policy hides. Expected: hidden.

redact-secret0.1.0-beta.14
94%948 of 1,006 hidden
  • Hidden 948
  • Partly readable 2
  • Readable 56
gitleaks8.30.1
50%506 of 1,006 hidden
  • Hidden 506
  • Partly readable 1
  • Readable 499
Show the 466 files with different results

2 / 2

Safe text that must be left alone

1,880 test files. Text this project’s policy leaves alone. Expected: left alone.

redact-secret0.1.0-beta.14
99.5%1,871 of 1,880 left alone
  • Left alone 1,871
  • Flagged 9
gitleaks8.30.1
97%1,828 of 1,880 left alone
  • Left alone 1,828
  • Flagged 52
Show the 55 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

Hidden by default

Project policy is this project’s own masking rule. Other tools are not built to follow it, so a difference here reflects scope, not accuracy. Show anyway.

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

gitleaks8.30.1

Built to find secrets in git history, files and directories before they are committed.

Ran as: Directory scan · default rules

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

517 test files whose provider family one of gitleaks’ rules targets. Values this project’s own masking policy hides. Expected: hidden.

redact-secret0.1.0-beta.14
90%463 of 517 hidden
  • Hidden 463
  • Partly readable 1
  • Readable 53
gitleaks8.30.1
60%311 of 517 hidden
  • Hidden 311
  • Partly readable 1
  • Readable 205
Show the 174 files with different results

2 / 2

Safe text that must be left alone

576 test files whose provider family one of gitleaks’ rules targets. Text this project’s policy leaves alone. Expected: left alone.

redact-secret0.1.0-beta.14
99.8%575 of 576 left alone
  • Left alone 575
  • Flagged 1
gitleaks8.30.1
97%561 of 576 left alone
  • Left alone 561
  • Flagged 15
Show the 16 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • gitleaks 8.30.1: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 8.30.1, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

1,440 test files. Secrets in formats the provider itself documents. Expected: hidden.

redact-secret0.1.0-beta.14
99%1,422 of 1,440 hidden
  • Hidden 1,422
  • Partly readable 2
  • Readable 16
trufflehog3.97.4
40%578 of 1,440 hidden
  • Hidden 578
  • Partly readable 12
  • Readable 850
Show the 844 files with different results

2 / 2

Safe text that must be left alone

167 test files. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%167 of 167 left alone
  • Left alone 167
  • Flagged 0
trufflehog3.97.4
98%163 of 167 left alone
  • Left alone 163
  • Flagged 4
Show the 4 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

722 test files whose provider family one of trufflehog’s rules targets. Secrets in formats the provider itself documents. Expected: hidden.

redact-secret0.1.0-beta.14
99.7%720 of 722 hidden
  • Hidden 720
  • Partly readable 0
  • Readable 2
trufflehog3.97.4
78%564 of 722 hidden
  • Hidden 564
  • Partly readable 9
  • Readable 149
Show the 156 files with different results

2 / 2

Safe text that must be left alone

73 test files whose provider family one of trufflehog’s rules targets. Look-alikes, placeholders and near misses of provider-documented formats. Expected: left alone.

redact-secret0.1.0-beta.14
100%73 of 73 left alone
  • Left alone 73
  • Flagged 0
trufflehog3.97.4
97%71 of 73 left alone
  • Left alone 71
  • Flagged 2
Show the 2 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

548 test files. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.

redact-secret0.1.0-beta.14
98%539 of 548 hidden
  • Hidden 539
  • Partly readable 3
  • Readable 6
trufflehog3.97.4
41%225 of 548 hidden
  • Hidden 225
  • Partly readable 3
  • Readable 320
Show the 314 files with different results

2 / 2

Safe text that must be left alone

1,866 test files. Look-alikes and near misses of those formats. Expected: left alone.

redact-secret0.1.0-beta.14
99%1,852 of 1,866 left alone
  • Left alone 1,852
  • Flagged 14
trufflehog3.97.4
97%1,804 of 1,866 left alone
  • Left alone 1,804
  • Flagged 62
Show the 66 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

336 test files whose provider family one of trufflehog’s rules targets. Secrets whose format is backed by a scanner’s rules, with no provider documentation. Expected: hidden.

redact-secret0.1.0-beta.14
97%327 of 336 hidden
  • Hidden 327
  • Partly readable 3
  • Readable 6
trufflehog3.97.4
67%225 of 336 hidden
  • Hidden 225
  • Partly readable 1
  • Readable 110
Show the 102 files with different results

2 / 2

Safe text that must be left alone

1,045 test files whose provider family one of trufflehog’s rules targets. Look-alikes and near misses of those formats. Expected: left alone.

redact-secret0.1.0-beta.14
99%1,038 of 1,045 left alone
  • Left alone 1,038
  • Flagged 7
trufflehog3.97.4
95%990 of 1,045 left alone
  • Left alone 990
  • Flagged 55
Show the 56 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

Hidden by default

Project policy is this project’s own masking rule. Other tools are not built to follow it, so a difference here reflects scope, not accuracy. Show anyway.

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

1,006 test files. Values this project’s own masking policy hides. Expected: hidden.

redact-secret0.1.0-beta.14
94%948 of 1,006 hidden
  • Hidden 948
  • Partly readable 2
  • Readable 56
trufflehog3.97.4
11%111 of 1,006 hidden
  • Hidden 111
  • Partly readable 0
  • Readable 895
Show the 837 files with different results

2 / 2

Safe text that must be left alone

1,880 test files. Text this project’s policy leaves alone. Expected: left alone.

redact-secret0.1.0-beta.14
99.5%1,871 of 1,880 left alone
  • Left alone 1,871
  • Flagged 9
trufflehog3.97.4
98%1,846 of 1,880 left alone
  • Left alone 1,846
  • Flagged 34
Show the 43 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

Hidden by default

Project policy is this project’s own masking rule. Other tools are not built to follow it, so a difference here reflects scope, not accuracy. Show anyway.

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Runtime library

redact-secret0.1.0-beta.14

Built to redact secrets from text at runtime: logs, prompts and tool output. Personal data only when switched on.

Ran as: Published npm package · default detectors

Measured in this run, 2026-10-07

Repository scanner

trufflehog3.97.4

Built to find and verify secrets in repositories and other sources. Verification is off here.

Ran as: Filesystem scan · verification disabled

Observed in the official run sha256:4bec6e539482…, 2026-10-07

Read this first

The redact-secret team wrote these test files and the expected answer for each, mostly to check formats redact-secret lists, and tuned redact-secret against them. A tool built for a different job can leave more of them readable. That describes scope. It is not a grade.

1 / 2

Secrets that must be hidden

519 test files whose provider family one of trufflehog’s rules targets. Values this project’s own masking policy hides. Expected: hidden.

redact-secret0.1.0-beta.14
96%499 of 519 hidden
  • Hidden 499
  • Partly readable 1
  • Readable 19
trufflehog3.97.4
18%96 of 519 hidden
  • Hidden 96
  • Partly readable 0
  • Readable 423
Show the 403 files with different results

2 / 2

Safe text that must be left alone

631 test files whose provider family one of trufflehog’s rules targets. Text this project’s policy leaves alone. Expected: left alone.

redact-secret0.1.0-beta.14
100%631 of 631 left alone
  • Left alone 631
  • Flagged 0
trufflehog3.97.4
96%607 of 631 left alone
  • Left alone 607
  • Flagged 24
Show the 24 files with different results

Where this comes from

  • redact-secret 0.1.0-beta.14 (published package), measured in the same run as this page: 2026-10-07, run sha256:4bec6e539482ad55f5d2e9ad25d84b5958d24050ada07271a33d50c6d4118586.
  • trufflehog 3.97.4: Observed in the official run sha256:4bec6e539482…, 2026-10-07. Version pinned in the repository; its own rules checked against the pinned rule file 3.97.4, reviewed 2026-09-30.
  • Denominator: 7,036 cases of the public-evidence-snapshot population, from the official credential-eval 0.1.0-alpha.16 run sha256:4bec6e539482… on evidence snapshot-2026.10.06.4. Every count on this page is of those cases; the regression and policy populations were run separately and are not added in. Every population.
  • Evidence levels and file kinds are the ones on the report. The same rows feed it; this page regroups them by file, where the report counts spans, so a file with several secrets counts once here. Open the report.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

Runtime library

redact-secret0.1.0-beta.14

Ran as: PII switched on (pii:global, pii:us) · published package

Run 2026-10-07

Runtime library

flare-redact1.6.1

Ran as: Defaults · published package

Run 2026-10-07

Read this first

redact-secret finds personal data only when PII is switched on, and by its own rules it leaves values that standards reserve for examples alone. Other tools make other choices. Where they differ, that is a different rule, not a grade.

Runtime preview, not peer accuracy measurement. These are the made-up texts from the runtime comparison, counted by text. Separate bounded local default type/range observations are listed on the PII evaluation page when validated. Reserved or example values follow authored neutral expectations; changed output cannot establish truth.

1 / 3

Personal data that looks real

8 texts. Made-up emails, cards, bank accounts, phone numbers and a US SSN that look like the real thing. Expected: hidden.

redact-secret0.1.0-beta.14
8 of 8hidden
  • Hidden 8
  • Left some or all 0
flare-redact1.6.1
4 of 8hidden
  • Hidden 4
  • Left some or all 4

Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.

Hidden by redact-secret, not hidden by flare-redact4

  • IP address
  • US Social Security no.
  • US phone number
  • Phone, Korean label

Hidden by flare-redact, not hidden by redact-secret0

None. All 4 texts flare-redact hid, redact-secret hid too.

2 / 3

Values made for examples, or failing a basic check

8 texts. Standards reserve some of these for examples: example.com, 555 phone numbers, documentation IP ranges, test card numbers. redact-secret leaves reserved values alone on purpose. Other tools may hide them on purpose. Neither is marked right here. Expected: depends on the rule, so no percentage.

redact-secret0.1.0-beta.14
2 of 8hidden
  • Hidden 2
  • Left some or all 6
flare-redact1.6.1
3 of 8hidden
  • Hidden 3
  • Left some or all 5

Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.

Hidden by redact-secret, not hidden by flare-redact1

  • Social Security no.

Hidden by flare-redact, not hidden by redact-secret2

  • example.com email
  • Test card number

3 / 3

Values with words around them

8 texts. The same kind of made-up values next to English and Korean labels, and next to words like “example” that say they are not real. Expected: depends on the rule, so no percentage.

redact-secret0.1.0-beta.14
0 of 8hidden
  • Hidden 0
  • Left some or all 8
flare-redact1.6.1
3 of 8hidden
  • Hidden 3
  • Left some or all 5

Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.

Hidden by redact-secret, not hidden by flare-redact0

None. redact-secret has no texts hidden here.

Hidden by flare-redact, not hidden by redact-secret3

  • Email, English label
  • Email, Korean label
  • Email, Korean label, decomposed form

Where this comes from

  • Full peer accuracy qualification remains unready. Bounded local default type/range observations preserve unsupported sensitivity, action and context quantities as withheld. Local peer scope and public artifacts.
  • redact-secret 0.1.0-beta.14 with pii:global and pii:us, and flare-redact 1.6.1 at its defaults, each on the same made-up texts, run 2026-10-07 (benchmarks/inputs/runtime/runtime-comparison-pii-global-us.json). The inputs are described by kind only; their text is never published.
  • “Hidden” means every value in the text came back replaced. Partly hidden counts as “Left some or all”.
  • The same texts and outcomes, with times, are on the runtime comparison. Open the runtime comparison.

Comparison

Put one tool next to redact-secret

Pick a tool. Both read the same test files. Each question says what the file expects, and each tool gets its own row: how often it matched that answer. Nothing here is scored or ranked.

Runtime library

redact-secret0.1.0-beta.14

Ran as: PII switched on (pii:global, pii:us) · published package

Run 2026-10-07

Runtime library

OpenRedaction1.1.5

Ran as: Defaults · published package

Run 2026-10-07

Read this first

redact-secret finds personal data only when PII is switched on, and by its own rules it leaves values that standards reserve for examples alone. Other tools make other choices. Where they differ, that is a different rule, not a grade.

Runtime preview, not peer accuracy measurement. These are the made-up texts from the runtime comparison, counted by text. Separate bounded local default type/range observations are listed on the PII evaluation page when validated. Reserved or example values follow authored neutral expectations; changed output cannot establish truth.

1 / 3

Personal data that looks real

8 texts. Made-up emails, cards, bank accounts, phone numbers and a US SSN that look like the real thing. Expected: hidden.

redact-secret0.1.0-beta.14
8 of 8hidden
  • Hidden 8
  • Left some or all 0
OpenRedaction1.1.5
7 of 8hidden
  • Hidden 7
  • Left some or all 1

Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.

Hidden by redact-secret, not hidden by OpenRedaction1

  • US Social Security no.

Hidden by OpenRedaction, not hidden by redact-secret0

None. All 7 texts OpenRedaction hid, redact-secret hid too.

2 / 3

Values made for examples, or failing a basic check

8 texts. Standards reserve some of these for examples: example.com, 555 phone numbers, documentation IP ranges, test card numbers. redact-secret leaves reserved values alone on purpose. Other tools may hide them on purpose. Neither is marked right here. Expected: depends on the rule, so no percentage.

redact-secret0.1.0-beta.14
2 of 8hidden
  • Hidden 2
  • Left some or all 6
OpenRedaction1.1.5
4 of 8hidden
  • Hidden 4
  • Left some or all 4

Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.

Hidden by redact-secret, not hidden by OpenRedaction1

  • Social Security no.

Hidden by OpenRedaction, not hidden by redact-secret3

  • Example IP address
  • Test card number
  • 555 phone number

3 / 3

Values with words around them

8 texts. The same kind of made-up values next to English and Korean labels, and next to words like “example” that say they are not real. Expected: depends on the rule, so no percentage.

redact-secret0.1.0-beta.14
0 of 8hidden
  • Hidden 0
  • Left some or all 8
OpenRedaction1.1.5
3 of 8hidden
  • Hidden 3
  • Left some or all 5

Each list holds the texts one tool hid and the other did not (readable or only partly hidden). A list is empty when every text one tool hid, the other hid too; that says nothing about the rest of its results, which are in its bar above.

Hidden by redact-secret, not hidden by OpenRedaction0

None. redact-secret has no texts hidden here.

Hidden by OpenRedaction, not hidden by redact-secret3

  • Phone, English label
  • Phone, Korean label
  • IP after “documentation”

Where this comes from

  • Full peer accuracy qualification remains unready. Bounded local default type/range observations preserve unsupported sensitivity, action and context quantities as withheld. Local peer scope and public artifacts.
  • redact-secret 0.1.0-beta.14 with pii:global and pii:us, and OpenRedaction 1.1.5 at its defaults, each on the same made-up texts, run 2026-10-07 (benchmarks/inputs/runtime/runtime-comparison-pii-global-us.json). The inputs are described by kind only; their text is never published.
  • “Hidden” means every value in the text came back replaced. Partly hidden counts as “Left some or all”.
  • The same texts and outcomes, with times, are on the runtime comparison. Open the runtime comparison.